Executive brief
A security vulnerability exists in Microsoft Office, the widely used suite of productivity applications. An attacker could exploit this flaw to run unauthorized code on a user's computer, potentially leading to a full system takeover or data theft. This typically requires a user to open a specially crafted malicious file provided by the attacker.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office, identified as CWE-822 (Untrusted Pointer Dereference) by the vendor. The vulnerability is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can exploit this to execute arbitrary code with the privileges of the logged-in user. While the attack vector is local, it requires user interaction (UI:R), such as opening a malicious document. Microsoft has released information regarding this vulnerability in their security update guide.
Affected products
- Microsoft Office
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory